← All industries
Industry deep dive

US healthcare — HIPAA Security Rule, PHI kept on-premise

For hospitals, health systems, health plans and health-tech business associates: continuous, technical evidence for the risk analysis the HIPAA Security Rule already requires, a testing cadence ready for the one HHS has proposed, and PHI and exploit evidence that never leave the hospital network.

The HIPAA Security Rule already requires an accurate and thorough assessment of the risks and vulnerabilities to electronic protected health information (45 CFR 164.308(a)(1)(ii)(A)) and a periodic technical and nontechnical evaluation (164.308(a)(8)), but it sets no testing frequency. The HHS proposal of January 6, 2025 (90 FR 898) would add one: vulnerability scans at least every six months and penetration testing at least once every 12 months. As of September 2026 it is still a proposal: no final rule has been published in the Federal Register, and the latest regulatory agenda entry targets final action for July 2027. The breach clock is already in force: individuals are notified no later than 60 calendar days after discovery.

What is on the US healthcare CISO's desk

A risk analysis that reflects real vulnerabilities

164.308(a)(1)(ii)(A) asks for an accurate and thorough assessment of risks and vulnerabilities to ePHI. A questionnaire with no technical testing is hard to defend as accurate on a network nobody has tried to break into.

The proposed six-month and 12-month floors

Proposed, not in force, and the final text may change. Building the testing program now is cheaper than retrofitting it to a compliance date, but no one should tell the board it is already required.

60 days from discovery, 500 or more to HHS

Individuals are notified within 60 calendar days of discovery (164.404). A breach affecting 500 or more individuals is reported to HHS at the same time; smaller breaches are logged and reported within 60 days after the end of the calendar year (164.408).

HHS 405(d) HICP as the practical baseline

The 2023 edition of Health Industry Cybersecurity Practices covers ten practices against five threats, ransomware and attacks on connected medical devices among them. For medium and large organizations, vulnerability management includes penetration testing and attack simulation.

How Zero Hunt fits a US health system

Pillar 1 — Generative Pentest

Technical evidence for the risk analysis

The 10-agent swarm tests what an attacker can actually reach: black box from outside the network, gray box with a standard clinical user account. Each finding records whether the vulnerability was exploited, which is what turns a risk register into an accurate one. EHR, PACS and lab systems can stay out of scope or at observe-only autonomy until you approve more, and five autonomy levels decide what waits for a human.

Pillar 2 — AI Traffic Analysis

Detection where endpoint agents cannot run

AI traffic analysis on the appliance GPU flags exfiltration, command-and-control and mid-encryption ransomware activity, including on segments with medical devices that cannot host an agent. The signed timeline of what was seen and when feeds the breach risk assessment and the 60-day notification decision, which remains yours.

Pillar 3 — Automatic Compliance

HIPAA evidence, signed and kept in-house

Findings are mapped to the Security Rule safeguards (164.308, 164.310, 164.312) and to the breach notification provisions (164.402 to 164.410), with the requirements from the 2025 proposal tracked separately and marked as proposed. Every attack attempt is an Ed25519-signed entry in a hash chain, and exported reports are ECDSA-signed.

Capability emphasis for US healthcare

  • ▸PHI and exploit evidence stay on the hospital network: private AI on the appliance, no external AI API
  • ▸Scan and penetration test schedules you can set to the proposed six-month and 12-month floors, or tighter
  • ▸Observe-only autonomy for clinical systems and medical-device segments until you approve more
  • ▸Evidence mapped once to HIPAA, NIST CSF, SOC 2 and ISO 27001 from one record store
  • ▸Air-gapped mode for research or isolated clinical networks: signed updates on physical media, no internet dependency

Who buys this in US healthcare

CISO sponsoring; the HIPAA security official named under 164.308(a)(2) co-signing the risk analysis; the privacy officer using the incident timeline for breach assessments; clinical engineering agreeing the scope for medical devices; CIO and CFO authorizing because the evidence builds up all year instead of once a year, without putting PHI on another vendor platform.

Frameworks mapped for this sector, worldwide

The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:

Global / cross-industry
  • NIST Cybersecurity Framework
  • SOC 2
  • ISO/IEC 27001:2022
  • CIS Critical Security Controls v8
United States
  • HIPAA Security Rule

Why this sector runs its AI red team on-premise, on private AI →

Go deeper on the regulations

Want to see this against your environment?

A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.